main

Microsoft issues emergency Windows patch

Slimy   on 03 April 2007 - 22:39 · 19 comments & 6817 views

Advertisement (Why?)
Microsoft has released an update that fixes seven separate Windows vulnerabilities, all of which were rated "critical" by the software giant. As expected, the release patches the way Windows processes .ani Animated Cursor files – Microsoft decided to break its patch cycle because attackers were finding more ways to exploit the flaw in its Windows operating system. Microsoft was first notified of the flaw in December 2006 by security vendor Determina. "I have no idea why they didn't do this earlier," said Nand Mulchandani, Determina's vice president of marketing.

Windows users are strongly encouraged to install the patch because the .ani flaw can be used to exploit computers running virtually any version of Windows, including Vista, even if they are running non-Microsoft browsers like Firefox and Opera, Mulchandani said. "We have more than 400 different URLs identified and related to attacks, and multiple e-mails have been sent out that direct people back there. We have proof that organized groups are now launching attacks," said Ken Dunham, director of malicious code intelligence with iDefense. Exploit code for the flaw has now been added to the widely used Metasploit hacking tool, and there are automated malicious Web site generation tools available, he added.

Link: Forum Discussion (Thanks JorgeIvan)
News source: InfoWorld

Post a comment · Send to friend Comments · There are 19 additional comments
(3 replies) #1 theblazingangel on 04 Apr 2007 - 00:04
#1.1 lbmouse on 04 Apr 2007 - 14:14
#1.2 vetmarkjensen on 04 Apr 2007 - 14:38
Quote - (lbmouse said @ #1.1)
God, I love Linux and all, but I am sick of the trolling frequently in your posts.
#1.3 lbmouse on 04 Apr 2007 - 16:19
It was a joke MJ . If you want to call it trolling, that's fine. I consider it being a "squeaky wheel". My goal is to get the attention of people that can change problems I see in my industry (not other posters)... in particular, Microsoft. They are the largest provider of tools that we use.
(3 replies) #2 Xinok on 04 Apr 2007 - 00:20
First, March 2007, a month with no security patches:
http://www.neowin.net/index.php?act=view&id=38652

Now April 2007, we read:
Microsoft was first notified of the flaw in December 2006 by security vendor Determina...

Makes you think...
#2.1 baskingridge on 04 Apr 2007 - 02:50
fixing bugs is bad, go linux
#2.2 XP-RTM on 04 Apr 2007 - 02:58
Quote - (baskingridge said @ #2.1)
fixing bugs is bad, go linux


I like linux but don't you dare say linux is bug free
#2.3 Esvandiary on 04 Apr 2007 - 11:28
Nothing's bug free (with the possible exception of some space shuttle stuff )
But... linux bugs tend not to be able to take out your entire PC.
(Disclaimer: written from a laptop running XP SP2. Not trying to troll, just trying to say what the last guy seemingly couldn't. )
#3 bryan09 on 04 Apr 2007 - 03:35
Installed Time to reboot. Thanks
#4 DaViD_BRaNDoN on 04 Apr 2007 - 04:40
Checked using Windows Update on Windows Vista but patch found...?
#5 dl0711 on 04 Apr 2007 - 05:57
Direct Download Link for the ones who cant see it on Windows Update

Direct Download: http://www.download.windowsupdate.com/msdo...80ef78f7af0.msu
#6 nub on 04 Apr 2007 - 07:47
I got this update and it automatically rebooted which was strange.
(1 reply) #7 bmaher on 04 Apr 2007 - 10:13
I still cant see why we cant have a "download as they're released" system, where they can be downloaded via WU as soon as theyre done.

i dont see the need for "patch tuesday"
#7.1 WindowsNT on 04 Apr 2007 - 11:36
There is a very good reason for "patch Tuesday". I don't know about you but many network administrators and people like me do not like to reboot systems every other day for a patch that just got released.

This used to be the system that MS went with but opted for a monthly system that's more predictable so we know on a given Tuesday to expect some updates.

There is a Microsoft mailing list that one can subscribe to get to advanced warning of what updates are comming up and also this is an emergency update that was released outside the 2nd Tuesday of the month cycle that is known as patch Tuesday.
(4 replies) #8 Oblivion on 04 Apr 2007 - 10:25
i installed it just now and it rebooted my system and upon booting it said something about user32.dll being moved into the memory.
#8.1 the_guy on 04 Apr 2007 - 10:33
That's a known issue. Just install KB935448 to fix the problem.

the_guy
#8.2 ec4912 on 04 Apr 2007 - 11:45
Thanks, I get the same message.
#8.3 +mrbester on 04 Apr 2007 - 15:35
Son of a...
Well, that's good to know; I bunged an extra 2GB of RAM in my box just before WU downed the update and that error got me worried...

edit: why validation is required I'd love to know, seeing as it's their freely available patch that caused the problem
#8.4 ec4912 on 04 Apr 2007 - 20:36
Wow, that's really messed up.

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)